Authorization bypass in Quarkus
High severity
GitHub Reviewed
Published
Dec 9, 2023
to the GitHub Advisory Database
•
Updated Aug 2, 2024
Package
Affected versions
>= 2.14.0, < 3.5.3
< 2.13.9.Final
Patched versions
3.5.3
2.13.9.Final
Description
Published by the National Vulnerability Database
Dec 9, 2023
Published to the GitHub Advisory Database
Dec 9, 2023
Reviewed
Dec 12, 2023
Last updated
Aug 2, 2024
A flaw was found in Quarkus. This issue occurs when receiving a request over websocket with no role-based permission specified on the GraphQL operation, Quarkus processes the request without authentication despite the endpoint being secured. This can allow an attacker to access information and functionality outside of normal granted API permissions.
References